Skip to the page
LotPost

What LotPost knows about you

Most policies describe categories. This one names the fields. Every one is listed below, and your cars are not among them.

In force 9 September 2026 The extension and this site

The short version

  • Your inventory stays on your computer. The cars, the photos, the drafts and your marketplace logins are read and kept in this browser and are never uploaded to us.
  • We count postings, not cars. To know a seat is being used we record which marketplace, when, whether it worked, and a one-way reference to the car. Not the car.
  • Nothing is sold, shared or advertised against. There is no analytics service, no advertising pixel and no third party receiving your data.

What stays on your computer

LotPost reads your inventory from your own website and keeps it in this browser's own storage. It stays there until you remove the extension or clear it yourself. That includes every car and its details, every photo, every listing draft LotPost prepares, your settings and field mappings, and the record of what you have posted.

LotPost fills the marketplace form in a tab you are already signed into. It does not hold your Facebook or Kijiji password, and it cannot: it types into the page the same way you would, in your own signed-in browser. No car is ever posted from our server.

Everything that leaves it

Four requests, and they are all here. Every one goes to your own LotPost account server. The fields listed are the whole body of each request, and that is enforced rather than promised: the server rejects any field it was not told to expect, so a future version cannot quietly add one to this list without the list changing too.

POST /api/pair Once, when you press Connect and type the code from your dashboard.
code The eight characters your dashboard just showed you. It is spent the moment it is used and never works twice.
GET /api/licence On a timer, and when the panel opens, to ask whether this seat is still live.

No body at all. The request carries your seat's token so we know which seat is asking, and nothing else.

POST /api/events Once per posting, so a seat can be metered against its plan.
target The word facebook or the word kijiji. Nothing else is accepted.
ts When it happened.
outcome published, failed or aborted.
vehicleHash A one-way SHA-256 reference to the car, computed on your computer before it is sent, so the car cannot be read back out of it. Our server then re-hashes it with a secret of its own before it touches disk. This is the closest thing to a car that ever crosses the wire.
eventId A random identifier, so that if the request has to be retried the same posting is not counted twice.
POST /api/diag Only when you press Send diagnostics. Never on its own.
items At most 100 error records, each one a time, a short code and a message of at most 500 characters. These are LotPost's own error messages about what went wrong, kept on your computer until you choose to send them.

LotPost reads two other kinds of page and neither one sends us anything: your own inventory feed, at the address you gave it, and the marketplace page it is filling. Everything it learns from those stays on your computer.

What we never ask for

These are not fields we choose not to read. There is no field for them, and a request carrying one is rejected before it is looked at.

  • A VIN, a stock number, a price, a mileage or a title status.
  • A photo, a listing URL or the text of a listing.
  • A buyer, a message, a lead or anyone's contact details.
  • Your Facebook or Kijiji password, or anything from those accounts.
  • Your browsing on any other site. LotPost reads two marketplace addresses and whichever inventory site you point it at yourself.

The permissions Chrome shows you

Chrome lists these when you install. Here is what each one is actually for.

storage Keeps your inventory, drafts and settings in this browser. The unlimited variant is there because a large lot with photos outgrows the small default.
tabs Opens the marketplace tab it is filling and notices when that page finishes loading.
scripting Types into the marketplace form, and reads the inventory page you point it at.
alarms Picks a paused job back up at the right time, instead of holding a timer open.
notifications Tells you a run finished or stopped.
downloads Saves a file to your computer when you ask for one.
sidePanel The panel LotPost runs in.
host access facebook.com/marketplace and kijiji.ca, the only two sites LotPost may read or type into without asking you first.
optional host access Your own inventory site, requested one site at a time, by you, when you connect your inventory. Chrome asks before it is granted and you can take it back.

Deleting all of it

Removing the extension deletes everything it kept on your computer, because all of it lives in this browser's own storage and goes with it.

On our side a seat holds your account details and the posting counts described above. Write to us and we will delete the account and everything metered against it. There is no copy anywhere else, because there is no third party.

Who to write to

LotPost is made by Kavalsia Inc., an Ontario corporation. Write to us about anything on this page, including deleting your account, and a person will answer.

Kavalsia Inc.

312 Greenwood Drive
Angus, Ontario L0M 1B4
Canada
Ontario Corporation Number 1000576319

A contact address is being set up and will be published here before the extension is listed.